Latest News  
2010-03-01 13:40:35 : ShmooCon 2010 Videos
Videos from this year's conference are now online. We're still missing a few speaker slides - we'll try to have those posted by the end of the week.
2010-02-18 15:44:37 : Thanks and Updates
Well, the snow didn't seem to stop us one bit. Thanks so much to everyone who braved the weather and spent the weekend with us. As reported in the 0wn the Con session, we had roughly 1340 people show up out of the expected 1550. Not bad considering the obstacles faced in getting to the DC area during a record snowfall. ShmooCon attendees are hardcore!
A number of you were with us virtually via the ustream feed. Yes, there were a few hiccups here and there but we learned a lot and we'll definitely be doing it again next year. If you missed those, rest assured that we're actively working to get the videos of the talks up and online. We'll make an announcement here when we're finished.
What else?
Final donation amounts for T-Shirt Charities are as follows:
- Hackers for Charity - $3324
- EFF - $2704
- American Red Cross - $2284
We've got a few Lost and Found items to report. If you think one of these items is yours send identifying information to info@shmoocon.org:
- A blue SRA Bag with items inside
- A camera
- A phone
- A black Nokia bag with items inside
That's it for now. More to come soon.
2010-02-04 15:03:25 : Just to be clear
Shmoocon is like the postal service. Come rain, come snow, come sleet - we will deliver. The con will go on as planned.
2010-02-03 15:30:59 : ShmooCon Live Streaming Video
We're still on track to do the live streaming during the con. You will be able to watch at:
https://www.shmoocon.org/video.html
Nothing to see there yet, but now you know. We'll post an update on Friday.
2010-02-01 23:16:12 : Oh the Weather Outside....
is potentially going to be snowy come ShmooCon weekend. Just a friendly reminder folks - check the forecast before traveling.
2010-01-14 22:30:50 : Now everyone can see ShmooCon
Either due to schedule conflicts, sold out tickets, or ninja attack, there are a number of folks who won't be joining us the first weekend in February.
To that end, we'll be streaming ShmooCon live via uStream this year. We've done some initial testing and we believe it should all go without a hitch. That said, as with anything you try for the first time, there will be hiccups. However, if all goes according to plan, you'll be able to watch live ShmooCon talks from the comfort of your couch and with no pressure to shower.
We'll post info on where to tune in to watch right prior to the start of the con.
2010-01-13 05:39:48 : Keynote Speakers Announced
ShmooCon and The Shmoo Group are pleased to announce this year's keynote address. Steve Dispensa and Marsh Ray will be presenting their first hand account and technical details behind the discovery of the TLS Authentication Gap vulnerability.
The ShmooCon schedule is now online as are most of the talk descriptions. Check it out!
2010-01-01 17:52:20 : That was fast...
Another round of ticket sales, another adventure. The good news is the new server has way more capacity than the last and the webpage was responsive the entire time. The bad news is we inadvertently redirected the reservation code page to an insecure page (which the webserver won't allow). We updated the landing page with the right link once we realized the mistake, but at that point we were already so close to selling out that the majority of you were still effected.
The good news is we have logs and have already sent an email to everyone who made it through the reservation process. If you haven't received an email by now, please try again next year - but also please check back in the weeks leading up to the con as we have more surprises up our sleeves. No not more tickets, but good things none-the-less.
Happy New Year everyone. Our resolution? Do everything we can for a successful ticket sales experience for ShmooCon 2011.
2010-01-01 02:36:51 : Ticket Sales Tomorrow
Just a reminder - sales go live at NOON EST.
Happy New Year's Eve to all of you!
2009-12-20 19:47:44 : Contests!
ShmooCon just wouldn't be the same without the following events:
Hack-or-Halo - Two tournaments in one, pitting elite hacking know how against mad gaming skills.
Hacker Arcade - Our own high-tech version of gaming for tokens - crypto tokens!
Barcode Shmarcode - Back for the second year in a row, the idea here is to bring your barcode to ShmooCon in style.
TF2 Lan Party - Because gaming is fun.
ShmooBall Launcher Contest - ShmooCon is nothing without ShmooBalls and it was only a matter of time before this contest came into play.
Check it out!
2009-12-19 16:26:45 : More Speakers Announced
Here you go folks - this is almost everyone. We'll have bios and abstracts up by the end of the weekend.
- Blackberry Mobile Spyware - The Monkey Steals the Berries - Tyler Shields
- WiFi Bombs shaken not stirred - Ben Smith, Terrence Gareau
- honeyM: A Framework For Virtual Mobile Device Honeyclients - Karlo Navas, David Brasefield, Nate Grunzweig, TJ OConnor
- WLCCP - Analysis of a Potentially Flawed Protocol - Enno Rey, Oliver Roeschke
- Jsunpack-network Edition Release: JavaScript Decoding and Intrusion Detection - Blake Hartstein
- PCI: An Existential Threat To Security As We Know It? - Joshua Corman, Michael Dahn, Anton Chuvakin, Jack Daniel
- How To Be An RSol: Effective Bug Hunting in Solaris - Matt Hillman
- Bluetooth Keyboards: Who Owns Your Keystrokes? - Michael Ossmann
- Exposed | More: Attacking the Extended Web - Nathan Hamiel
- BaSO4: A Dynamic Dataflow Analysis Tool for Auditing and Reversing - Dion Blazakis
- A Tale of Infrastructural Weaknesses in Distributed Wireless Communication Services - Zack Fasel
- The New World of Smartphone Security - What Your iPhone Disclosed About You - Trevor Hawthorn
- Becoming Jack Flack: Real Life Cloak & Dagger - Taylor Banks, Adam Bregenzer
- De Gustibus - Adventures in Hacking Taste - Sandy Clark
- Flying Instruments-Only: Legal and Privacy Issues in Cloud Computing - Richard Goldberg
- Worst Practices in Facility Secuirty - Shane Lawson
- Tales from the Crypto - G. Mark Hardy
- Detection of rogue access points using clock skews: does it really work? - Sergey Bratus, Anna Shubina, Chrisil Arackaparambil
- Pulling the Plug: Security Risks in the Next Generation of Offline Web Applications - Michael Sutton
- Guest Stealing...The VMware Way - Justin Morehouse, Tony Flick
- Windows File Pseudonyms - Dan Crowley
- Information disclosure via P2P networks: Why stealing an identity via Gnutella is like clubbing baby seals. - Larry Pesce, Mick Douglas
2009-12-07 21:51:48 : More Speakers
Round 2 of Speaker Selection has been completed. The following talks are officially accepted:
- GPU vs. CPU Supercomputing Security Shootout - Collin Brack
- Closing the TLS Authentication Gap - Steve Dispensa and Marsh Ray
- Social Zombies II: Your Friends Need More Brains - Tom Eston, Kevin Johnson, Robin Wood
- Cyborg Information Security: Defense Against the Dark Arts - Esteban Gutierrez and Adam Cecchetti
- The Friendly Traitor: Our Software Wants to Kill Us - Kevin Johnson and Mike Poor
- Ring -1 vs. Ring -2: Containerizing Malicious SMM Interupt Handlers on AMD-V - Pete Markowsky
- Stealing Guests...The VMware Way - Justin Morehouse and Tony Flick
- GSM: SRSLY? - Chris Paget and Karsten Nohl
- The Splendiferous Story of Archive Team and the Rapidly Disappearing Digital Heritage - Jason Scott
2009-12-03 04:23:30 : 0wn the Con - the online version
Well, another round of ticket sales is in the books. Thanks to everyone who bought tickets (and thanks to those who tried but didn't make it). We've received a lot of feedback in the last few weeks including emails, tweets, blog posts, and even phone calls from our closest friends. Some was positive, some was negative - but given the amount of comments, we're going to address much of it here.
Ticket Sales Methodology:
We often get asked "why do you sell tickets the way you do?" The ShmooCon ticket sales process has really evolved through the years. However, for the last few, at the initial urging of our attendees, we've employed a "pay what you think its worth" model ala Burning Man. The idea is that you'd pay based on your ability to pay or what you think the value of the con really is. So we provided three price options, the uppermost of which has always scored you a free t-shirt. Other than that, the tickets all provide the same access. As we've stated before this has pretty much devolved into a "pay what you can get" scenario. There are many pros and cons associated with this, but overwhelmingly the feedback from last year was not to change the system.
And so ShmooCon ticket sales continue to be somewhat of an adventure. Demand has gone up each year, and the number of people trying to buy tickets at each sales cycle seems to have grown. Every single sales cycle has helped us learn more about our cart, our systems, and our attendees. We've constantly tried to make changes to the cart based on what we've learned; sometimes the changes work out, sometimes they don't. Honestly, ticket sales days are very stressful for us because even with testing and preparation, there are enough unknown variables to keep things exciting.
Examples of Lessons Learned:
When you say ticket sales will go live on Nov 1st - state a time. We had folks up at midnight in all time zones. (ShmooCon III)
However much memory you think is needed, it won't be enough (ShmooCon IV)
Unlimited amounts of Apache connections is a very bad thing (ShmooCon V)
Going Forward:
This year there have been a number of changes including more internal documentation to help us plan and execute, more external documentation so you know how things work, and a reserve then pay model based on what cons like BlizCon have done. We also threw in a CAPTCHA to stop the folks who had written bots to buy as many tickets as possible. Overall, these changes have had a positive effect on the registration system. Still, in the second round, there were obvious load issues on the server. We've got a new machine built and ready to replace the old one. The new machine has a lot more horsepower and we'll have it in place in time for the January 1st sales cycle.
As to what will happen with the sales model next year - we just don't know yet. We're reviewing data, crunching numbers and will be soliciting feedback over the next few months. There are a number of possibilities all with their own good and bad sides.
Limited Attendance:
ShmooCon limits attendance to a preset number. This, as many have pointed out, is very different from the standard hacker/security con. ShmooCon is not backed by a big corporation, ShmooCon is not out to dominate the conference industry, and ShmooCon isn't trying to steal all your money. We are, however, trying to throw a first rate con at a reasonable price and end up with an event that the attendees feel is valuable and pushes the information security ball forward. To help us plan better and to limit our potential financial liability, we limit the number of tickets we sell. We find this makes everyone happy and prevents us from losing our shirts if things go badly. It also helps us to create an environment for our attendees (think not too big, not too small) that is a big part of the ShmooCon experience.
Ultimately there are many more people who want to attend ShmooCon than we can accommodate. Woe is us, right? But we understand this is a real issue as many people who want to participate in ShmooCon are unable to get tickets. We do our best to get content online and make our conference as open as possible. We also support many other great cons throughout the world which over the years has included yStS, Phreaknic, ToorCon, LayerOne, and Notacon. If you can't make it to ShmooCon, or even if you can, check out these other worthy events.
Feedback:
Finally, we take all your feedback (positive and negative) very seriously. At every ShmooCon we host a talk called "0wn the Con" where we provide tons of info on our infrastructure, our organization, and our finances. The videos and slides from previous years are online and you're welcome to view them. The entire Shmoo Group and all the ShmooCon volunteers take ShmooCon seriously and we do our best to provide you the best con possible. So keep the feedback coming, and thanks for your help in making ShmooCon better.
2009-12-02 19:57:09 : Ticket Purchasing
The vast majority of you have already come back and purchased your reserved tickets - Thank you! For the small number of you who haven't, you've got until noon EST tomorrow, Dec. 3, to get that done.
If you've written info regarding your purchase (international inquiries and others), you'll be hearing from us shortly if you haven't already.
Thanks again!
2009-12-01 17:12:43 : Round Two Ticket Sales
Before our news entry post about ticket sales being open could even post, we were sold out. This is a new Round Two ShmooCon record.
Those of you who got reservation codes can come back beginning at 1pm EST to complete your purchase. This will remain open for at least 24 hours. We will give notice here prior to shutting that down.
2009-11-30 18:01:19 : Ticket sales and other updates
Ticket Sales
2nd round of ticket sales begins tomorrow, Dec 1st at Noon EST. We'll be watching...
Speakers
The early round of speaker selection is done and we're happy to announce the beginning of our line up so far:
- Economics of Cyber Crime - Peter Guerra
- Better Approaches to Physical Tamper Detection - Roger G. Johnston and Jon S. Warner
- DIY Hard Drive Diagnostics: Understanding a Broken Drive - Scott Moulton
- Build your own Predator UAV @ 99.95% Discount - Michael Weigand
Sponsors
A big thanks to our newest sponsors:
More to come in the days and weeks to come - keep watching this space!
2009-11-19 16:11:37 : CFP closes tomorrow
Just a reminder that tomorrow, Friday, November 20, is the last day to turn in any CFP submissions. We will accept submissions up until midnight EST.
2009-11-12 19:31:19 : Updates
A few new features for all of you:
Lost your barcode? Regenerate it using our barcode generator.
Need a receipt? Get yours here.
2009-11-02 14:26:16 : Reserved Tickets
An overwhelming majority of folks who were able to reserve tickets yesterday have already come back to purchase - thank you! The rest of you have until Noon EST tomorrow (Tuesday) to redeem your reservation codes. After that, those tickets will be released and added into the numbers for the December sales date.
Also, yesterday was the early submission deadline for the CFP. We received a record 86 talks by midnight. We will be choosing a small number of talks from submissions received up to this point. If you're not selected this round, don't worry - you're still in the running. Haven't submitted yet? There's still time. You still have until the 20th to turn something in.
2009-11-01 22:20:30 : And so this stays at the top
Reposted:
Once you get your ticket, think about getting a room. Already booked a room? We know some of you have. Call back and get it moved into the ShmooCon Block.
Rooms at the Wardman Park Marriott will run $179/night for a single/double. Enter or reference code OCTOCTA when making your reservation to get this rate.
2009-11-01 22:19:40 : Round One Sold Out
In record time, at least for November ticket sales. Next round of tickets will be up for grabs on December 1st.
2009-11-01 18:20:27 : Link to Ticket Sales
It really was there folks...at the bottom of the page. Yes, we should have top posted and made it easier on all of you. It was an inadvertent overlook on our part and we're sorry.
That being said, it is a hacker con. Maybe next time we'll put the link in the middle. ;)
Also, there are still a small number of tickets in the system that age out as people don't complete the reservation process. You can continue to try to get a reservation code, but type fast as you'll be racing with others to try and get the same tickets. We'll notify you here when tickets are actually sold out.
One more mea culpa. We're aware we need to change the text that pops up when all tickets are in the reserve process and, at that moment, unavailable. While that won't really change anything, we feel it should be more informative than simply "come back in December."
2009-11-01 17:03:02 : Ticket Sales
Are live...get 'em while they're hot.
2009-11-01 13:55:20 : Hotel Code
Once you get your ticket, think about getting a room. Already booked a room? We know some of you have. Call back and get it moved into the ShmooCon Block.
Rooms at the Wardman Park Marriott will run $179/night for a single/double. Enter or reference code OCTOCTA when making your reservation to get this rate.
2009-10-31 19:27:17 : Important information regarding ticket sales
Folks, it's less than 24 hours until the first round of ticket sales. We've implemented some major changes this year and it's important that you understand the process prior to the rush tomorrow. Please visit and read the information on the registration page followed by the information on the cart page.